# Display a Value from a JSON Field

**URL:** <https://discuss.elastic.co/t/display-a-value-from-a-json-field/297178>\
**Category:** Kibana\
**Created:** [February 14, 2022, 6:25pm UTC](https://discuss.elastic.co/t/display-a-value-from-a-json-field/297178 "2022-02-14T18:25:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamiejackson](https://avatars.discourse-cdn.com/v4/letter/j/d07c76/32.png) [@jamiejackson](https://discuss.elastic.co/u/jamiejackson)\
**Post date:** [February 14, 2022, 6:25pm UTC](https://discuss.elastic.co/t/display-a-value-from-a-json-field/297178/1 "2022-02-14T18:25:08Z")

</div>

I see several related forums posts for this but as far as I can tell, nobody had any success.

In Elasticsearch/Kibana 6.7 (AWS-managed, for now). Say I have a field, `httpRequest.headers`, which has the following contents:

```json
{
  "name": "upgrade-insecure-requests",
  "value": "1"
},
{
  "name": "user-agent",
  "value": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.82 Safari/537.36"
}

```

I'd like to display the `user-agent` value in discover, preferably as the field `httpRequest.headers.userAgent`.

I understand that there's a way to do that on the fly and also a way to do it via a scripted field. However, I'm striking out.

Could you tell me exactly what/where I'd need to type in Discover to do it on the fly?  
Could you also tell me exactly how to create it as a scripted field in the Kibana UI?

Thanks!

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 15, 2022, 5:10pm UTC](https://discuss.elastic.co/t/display-a-value-from-a-json-field/297178/2 "2022-02-15T17:10:19Z")

</div>

If you would update to 7.11 or newer, You may use runtime field. I'm not sure it is possible with 6.7.

Send the following requiest via Dev Tools in Kibana

```auto
PUT /test_array/_mapping
{
  "runtime":{
    "userAgent":{
      "type":"keyword",
      "script": {
        "source": "for (map in params._source.headers){if (map['name']=='user-agent'){emit(map['value'])}}"
      }
    }
  }
}

```

That said, if you need such field, set the value to appropriate field at indexing time is better.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2022, 5:10pm UTC](https://discuss.elastic.co/t/display-a-value-from-a-json-field/297178/3 "2022-03-15T17:10:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
